Boards ask about CRA, NIS2 and the AI Act as if they were three IT projects with three deadlines. They are not. They are three views of the same duty of care, and the risk sits with leadership, not with engineering.
Underestimating scope
Leaders default to treating the Cyber Resilience Act as an engineering problem: patch the code, ship the update, done. It reaches procurement, supply chain, legal, service and sales. A purchasing team qualifying a component supplier is doing CRA work. A sales team promising a support period in a contract is doing CRA work. Scoping the obligation as an engineering task at the outset is the most expensive mistake a company makes, because every later decision inherits the wrong boundary.
Treating it as a project with an end date
CRA does not close when a product ships. It opens a lifecycle of duties: security updates for the whole support period, post-market monitoring, vulnerability handling, reporting obligations that trigger the moment something is found. A team staffed and funded as a one-off certification project performs well in year one and fails quietly in year two, once the launch budget is gone and the obligations are still running.
Evidence debt
Being compliant and being able to prove it are different things, and the CRA's duty of care standard cares about the second one. Evidence has to be built as the work happens: the risk assessment that shaped a decision, the sign-off on an essential requirement, the vulnerability report and what was done about it. Reconstructing that trail after the fact, under audit pressure or after an incident, is where the debt comes due, and it comes due at the worst possible moment.
Regulatory collision
CRA, NIS2 and the AI Act overlap in scope and in evidence, and national implementations of all three are still unsettled. Run them as three separate programmes and a company pays for three risk assessments, three sets of documentation and three audit trails that do not talk to each other, with three places for the same gap to hide. Run them as one control framework, and a risk assessment done once serves all three, because the underlying question, "what could go wrong and what did we do about it", does not change with the regulation asking it.
The meta-risk is market access
None of the above is really about the size of a fine. CRA non-conformity means a product cannot carry the CE mark, and a product without CE marking cannot be placed on the EU market. Getting classification, scope or timing wrong does not cost money first. It costs the right to sell in the EU, which is a different order of risk than the one most compliance budgets are sized for.
The fix is not a bigger compliance team. It is one evidence trail, built continuously, that answers CRA, NIS2 and AI Act questions from the same source instead of three.